Memory Consumption Issue in Go Programming Language by Google
CVE-2025-22868

Currently unrated

Key Information:

Vendor
Golang.org/x/oauth2
Status
Golang.org/x/oauth2/jws
Vendor
CVE Published:
26 February 2025

Summary

A vulnerability in the Go programming language allows an attacker to send a specially crafted malformed token, leading to unintended memory consumption during the parsing process. This behavior could facilitate potential denial-of-service conditions, making the application susceptible to interruptions in service.

Affected Version(s)

golang.org/x/oauth2/jws 0 < 0.27.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

jub0bs
.